Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag (CVE-2026-58439)
Gitea versions prior to 1.27.0 contain a vulnerability where the 'official' approval flag on pull request reviews is not re-evaluated when the PR's target branch is changed. This allows an attacker with write access to obtain an official approval on a PR targeting an unprotected branch and then retarget the PR to a protected branch, bypassing branch protection rules and merging without legitimate maintainer approval.
AI Analysis
Technical Summary
Gitea does not re-check the 'official' flag on existing pull request reviews when the PR's target branch is changed. The 'official' flag, which indicates if a reviewer's approval counts towards branch protection, is computed at review submission based on the target branch's approval whitelist and stored in the database. When the PR target branch changes, existing reviews are not updated or dismissed. At merge time, Gitea counts stored 'official=true' approvals without revalidating against the new branch's whitelist. An attacker with write access can exploit this by obtaining an official approval on a PR targeting an unprotected branch and then retargeting the PR to a protected branch, allowing merge without authorized approval.
Potential Impact
An attacker with write access to a repository can bypass branch protection rules requiring approvals from designated reviewers. This enables merging code into protected branches without legitimate maintainer approval, potentially introducing unauthorized or malicious changes. The vulnerability does not require admin access or membership in the protected branch's approval whitelist.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict write access to trusted users only and monitor pull request target branch changes closely. Consider manual review of PR retargeting events to ensure approvals remain valid.
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag (CVE-2026-58439)
Description
Gitea versions prior to 1.27.0 contain a vulnerability where the 'official' approval flag on pull request reviews is not re-evaluated when the PR's target branch is changed. This allows an attacker with write access to obtain an official approval on a PR targeting an unprotected branch and then retarget the PR to a protected branch, bypassing branch protection rules and merging without legitimate maintainer approval.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Gitea does not re-check the 'official' flag on existing pull request reviews when the PR's target branch is changed. The 'official' flag, which indicates if a reviewer's approval counts towards branch protection, is computed at review submission based on the target branch's approval whitelist and stored in the database. When the PR target branch changes, existing reviews are not updated or dismissed. At merge time, Gitea counts stored 'official=true' approvals without revalidating against the new branch's whitelist. An attacker with write access can exploit this by obtaining an official approval on a PR targeting an unprotected branch and then retargeting the PR to a protected branch, allowing merge without authorized approval.
Potential Impact
An attacker with write access to a repository can bypass branch protection rules requiring approvals from designated reviewers. This enables merging code into protected branches without legitimate maintainer approval, potentially introducing unauthorized or malicious changes. The vulnerability does not require admin access or membership in the protected branch's approval whitelist.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict write access to trusted users only and monitor pull request target branch changes closely. Consider manual review of PR retargeting events to ensure approvals remain valid.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w5pg-649r-p6gg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-58439"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a600abd9c2644c7f8fe2ef3
Added to database: 07/22/2026, 00:11:41 UTC
Last enriched: 07/22/2026, 00:53:33 UTC
Last updated: 07/31/2026, 12:28:12 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.